Stored Cross-Site Scripting Vulnerability in Pharmacy POS PHP Script
CVE-2025-40724
What is CVE-2025-40724?
A vulnerability in the Pharmacy POS PHP Script allows attackers to exploit stored Cross-Site Scripting (XSS) by injecting malicious JavaScript through the u_medicine_name parameter in the /edit_medicine.php endpoint. This flaw can be used to execute arbitrary scripts in the context of the victim’s browser, potentially leading to the theft of sensitive information, including session cookies, and unauthorized actions performed on behalf of the user. It is critical for users and developers to implement mitigations to prevent XSS attacks and protect user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pharmacy POS PHP Script all versions
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
